Data leak

Bell Canada / CBC / Vice Motherboard

πŸ“… 2014-08-01
Primary Source β†—

Incident Details

Hacker collective NullCrew claimed responsibility for a breach of Bell Canada, Canada’s largest telecom, disclosed August 28 2014. Approximately 1.9 million email addresses and 76,000 names and active phone numbers were stolen. NullCrew used SQL injection to access Bell’s databases and published a portion of the data online. Bell confirmed the breach and stated that no financial or password data was taken. Bell notified affected customers by email. Several members of NullCrew were subsequently arrested and charged in the United States.

Technical Details

Initial Attack Vector
CWE-89: SQL Injection (hacker group NullCrew exploited SQL injection in Bell's systems)

Timeline

  1. 2014-08-01 Breach occurred
  2. 2014-08-28 Publicly disclosed
  3. 2014-08-28 Customers notified